Utopia Tech
SecurityAI-assisted1 min read

24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

Cybersecurity researchers have discovered over 36,000 Baseboard Management Controller (BMC) interfaces with IPMI protocol exposed to the public internet. Critically, 24,650 of these systems are leaking password-derived authentication hashes before login, creating a significant security vulnerability that could allow unauthorized access to server management functions.

UT

Utopia Tech

July 28, 2026 · 1 min read

Share

Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the 36,872 internet-exposed server-management interfaces running IPMI, 24,650 have been found to disclose password-derived authentication hashes before login due to

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content